$EPREFIX/usr/bin/c_rehash uses by default SSL_CMD=/usr/bin/openssl (without $EPREFIX). This causes it to use the base system openssl, which on my system (OS X 10.5) is version 0.9.7 and uses a hash function incompatible with the openssl in $EPREFIX. Because of this, all CA verifications done by the prefix openssl fail.
I prefixed the script now, without a bump because it has gone unnoticed for ages. Please sync in about an hour from now, and reemerge openssl.